This update of our 2025 report on ASM will once again cover the trends that are influencing this market segment and the essential capabilities required of solutions in this space, providing ratings of how well these solutions meet our expectations.
Inclusion Criteria
In this Leadership Compass, our main goal is to identify offerings that deliver automated continuous discovery and monitoring of assets and vulnerabilities. Based on our research findings, we will decide whether a solution fits our understanding of ASM and its capabilities. Therefore,
- Solutions that offer EASM, CAASM, TPRM, DRP capabilities
- There are other types of solutions that might be included in our compass, such as Continuous Threat Exposure Management (CTEM), Exposure Management, Next-Gen Vulnerability Management, Attack Surface Assessment (ASA), External Risk Management (ERM) , Attack Path Management , Digital Footprint, Automated Security Validation (ASV), and Digital Asset Discovery tools.
Exclusion Criteria
Although we aim to find out what offerings prevent attack vectors and reduce attack surface in this compass, those offerings must deliver certain capabilities and solutions. Thus,
- Solutions that do not offer proactive threat and vulnerability detection will be excluded from our compass.
- Vendors that offer only red teaming and pen testing will be excluded from our compass.
- Vendors that offer only reactive vulnerability management or breach & attack simulation will not take part in our compass.
- Vendors that operate in detection and response realms.
- Solutions that are not in production yet; for example, those that are early stage and are only in proof-of-concept stages.